IBIS Labs – Microsoft 365 / Graph Terms of Service

Effective Date: January 29, 2026
Entity: Ibis Laboratories Inc. (“Ibis Labs,” “we,” “us,” or “our”)

These Microsoft 365 / Microsoft Graph Terms of Service (“Graph Terms”) govern the use of IBIS Laboratories Inc.’s (“IBIS”) integrations with Microsoft 365 services through Microsoft Entra ID and Microsoft Graph (the “Integration”).

These Graph Terms supplement IBIS’s general Terms of Service and Privacy Policy and apply specifically to data accessed via Microsoft 365 integrations.

1. Scope of Integration

The Integration enables customers to connect Microsoft 365 services, including Outlook and Microsoft Teams, to IBIS in order to organize, contextualize, and manage operational work derived from unstructured communications.

Access to Microsoft 365 data is limited to the permissions explicitly approved by the customer or the customer’s administrator through Microsoft Entra ID consent.

2. Data Access and Permissions

Depending on the permissions granted, IBIS may access the following Microsoft 365 data:

- User profile information (such as name and email address)
- Email messages and related metadataAttachments associated with messages
- Microsoft Teams chat messages and related metadata
- Tenant and organizational identifiersI

BIS does not access Microsoft 365 data beyond the specific permission scopes explicitly approved through Microsoft Entra ID.

3. Purpose Limitation

IBIS accesses Microsoft 365 data solely for the purpose of providing the Integration, including:

- Interpreting and structuring operational communications
- Extracting tasks, milestones, documents, and contextual signals
- Reducing manual triage and administrative workload
- Supporting workflow continuity and background processing

IBIS does not use Microsoft 365 data for advertising, marketing, resale, or training generalized AI models. Customer data is not shared across tenants.

4. Background and Offline Access

Where approved, IBIS may retain secure authorization tokens to maintain access to approved Microsoft 365 data when users are not actively logged in (“offline access”). Offline access:

- Does not grant additional permissions beyond those explicitly approved
- Is used solely to support background processing and continuity of service
- Can be revoked at any time by a customer administrator through Microsoft Entra ID

5. Data Security and Handling

IBIS implements reasonable and industry-standard safeguards to protect Microsoft 365 data, including encryption in transit and at rest, least-privilege internal access controls, segregation of customer data by tenant, and monitoring and logging of access. Access to Microsoft 365 data is auditable through Microsoft Entra ID and Microsoft 365 audit logs. IBIS personnel may access customer data only as necessary to operate, support, or improve the service.

6. Data Retention and Deletion

Microsoft 365 data accessed via the Integration is retained only as long as necessary to provide the service. Customers may request deletion of Microsoft 365–derived data. Revoking Microsoft Entra ID consent immediately prevents IBIS from accessing Microsoft 365 data going forward.

7. Customer Responsibilities

Customers are responsible for obtaining any required internal approvals before granting Microsoft Entra ID consent, ensuring that use of the Integration complies with applicable laws and internal policies, and managing user access and permissions within their tenant.

8. No Impersonation or Hidden Access

IBIS does not impersonate users, bypass tenant policies, or access Microsoft 365 data without explicit authorization. Where messages are sent via Microsoft Teams or email, they are sent either as the authorized user (in delegated access scenarios) or clearly identified as originating from the IBIS application (in application access scenarios), depending on the permissions granted. All access is enforced by Microsoft Entra ID, Microsoft Graph permission scopes, Conditional Access policies, and Microsoft Teams Application Access Policies where applicable.

9. Changes to Integration or Permissions

IBIS may update the Integration over time. Any access to additional Microsoft 365 data or new permission scopes will require explicit customer or administrator consent prior to use.

10. Contact

Questions regarding these Graph Terms or IBIS’s Microsoft 365 integrations may be directed to:

IBIS Laboratories Inc.
Email: info@ibislabs.ai
Website: https://ibislabs.ai

Join our newsletter

Sign up to our mailing list below and be the first to know about new updates. Don't worry, we hate spam too.

© 2026 Ibis Laboratories, Inc.

Join our newsletter

Sign up to our mailing list below and be the first to know about new updates. Don't worry, we hate spam too.

© 2026 Ibis Laboratories, Inc.

Join our newsletter

Sign up to our mailing list below and be the first to know about new updates. Don't worry, we hate spam too.

© 2026 Ibis Laboratories, Inc.